password-reset-flaws
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent, but its purpose is to equip an AI agent with offensive account-takeover testing techniques against password reset/change flows. There is no clear malware behavior, no hidden exfiltration endpoint, and no untrusted installer chain, yet the capability itself carries high misuse potential and real-world impact if used outside authorized security testing.
Confidence: 91%Severity: 74%
Audit Metadata